CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
184 vulnerabilities with CWE-359
CVE-2025-3035
MEDIUM
Firefox < 137.0 - Unauthorized Document Title Exposure via AI Chatbot
CVSS 5.3
CVE-2025-26816
MEDIUM
Intrexx Portal Server <12.0.2 - Info Disclosure
CVSS 6.5
CVE-2025-27080
MEDIUM
AOS-CX - Info Disclosure
CVSS 6.0
CVE-2025-25042
MEDIUM
HPE AOS-CX Sensitive Information Exposure via REST Interface
CVSS 4.3
CVE-2025-1939
LOW
Firefox < 136.0 - Permission Spoofing via Custom Tabs Transition Animation
CVSS 3.9
CVE-2025-20060
HIGH
Dario Health USB-C Blood Glucose Monitoring System Android < 5.8.7.0.36 - Personal Health Information Exposure
CVSS 7.5
CVE-2025-20615
MEDIUM
Qardio Arm iOS - Unauthenticated Exposure of Sensitive Data in Plist File
CVSS 6.2
CVE-2025-0683
MEDIUM
Contec Health CMS8000 Patient Monitor - Info Disclosure
CVSS 5.9
CVE-2025-24355
HIGH
Updatecli <0.93.0 - Info Disclosure
CVSS 7.1
CVE-2024-13953
MEDIUM
ASPECT-Enterprise <3.* - Info Disclosure
CVSS 4.9
CVE-2024-42325
LOW
Zabbix 5.0.0-5.0.45 - Unauthorized Exposure of User Information via API user.get
CVSS 3.5
CVE-2024-10267
HIGH
transformeroptimus/superagi - Info Disclosure
CVSS 7.5
CVE-2024-13228
MEDIUM
Qubely - Advanced Gutenberg Blocks <1.8.13 - Info Disclosure
CVSS 4.3
CVE-2024-11216
HIGH
PozitifIK Pik Online <3.1.5 - Privilege Escalation
CVSS 7.6
CVE-2024-13217
MEDIUM
Jeg Elementor Kit <2.6.11 - Info Disclosure
CVSS 4.3
CVE-2024-12041
MEDIUM
Directorist: AI-Powered WordPress Business Directory Plugin - Info ...
CVSS 5.3
CVE-2024-13216
MEDIUM
HT Event - WordPress Event Manager Plugin for Elementor <1.4.7 - In...
CVSS 4.3
CVE-2024-13215
MEDIUM
Elementor Addon Elements <1.13.10 - Info Disclosure
CVSS 4.3
CVE-2024-11396
MEDIUM
Event Monster < 1.4.3 - Unauthenticated Information Exposure via Visitors List Export
CVSS 5.3
CVE-2024-41780
MEDIUM
IBM Jazz Foundation <7.1.0 - Info Disclosure
CVSS 4.2
CVE-2024-49765
MEDIUM
Discourse - Unauthorized Account Creation via Discourse Connect Bypass
CVSS 5.3
CVE-2024-11712
MEDIUM
WP Job Portal < 2.2.3 - Unauthenticated Exposure of Private Personal Information via getResumeFileDownloadById
CVSS 5.3
CVE-2024-42494
MEDIUM
Ruijie Reyee OS <2.320 - Info Disclosure
CVSS 6.5
CVE-2024-53258
MEDIUM
Autolab 3.0.0-3.0.2 - Unauthorized Submission Download via download_all_submissions Feature
CVSS 5.3
CVE-2024-49025
MEDIUM
Microsoft Edge Chromium < 131.0.2903.48 - Exposure of Private Personal Information
CVSS 5.4
Details
Vulnerabilities
184